← Vulnerability feed

Vulnerability record · CVE-2006-5397 · published 3 November 2006

CVE-2006-5397: X.org libx11 vulnerability

XX.Org · Libx11

The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.

2.1 CVSS 2.0 Low EPSS 0.36% · top 73.0%
2.1CVSS 2.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.

AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5397 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-31535X.org libx11 classic buffer overflow vulnerabilityLookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor reques…EPSS 11%9.8CVE-2018-14600X.org libx11 out-of-bounds write vulnerabilityAn issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resul…EPSS 9.3%9.8CVE-2018-14599X.org libx11 vulnerabilityAn issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious s…EPSS 4.8%9.8CVE-2016-7943Fedoraproject fedora out-of-bounds write vulnerabilityThe XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigg…EPSS 4.5%9.8CVE-2016-7942Fedoraproject fedora permissions and access controls vulnerabilityThe XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, wh…EPSS 4.5%9.3CVE-2007-1667X.org libx11 vulnerabilityMultiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagi…EPSS 4.6%7.8CVE-2023-43787X.org libx11 heap-based buffer overflow vulnerabilityA vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an intege…EPSS 0.48%7.8CVE-2020-14363X.org libx11 integer overflow vulnerabilityAn integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application …EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2006-5397), CISA KEV, FIRST EPSS (scores of 2026-10-04). This page is refreshed as NVD updates the record.